Acceptable Use Policy
Document
PACK & KIN STUDIO — ACCEPTABLE USE POLICY
Version: 1.0 · Status: Approved · Approved: 2026-09-07 · Approved by: Dax Barron, Mail and More LLC
Approved by the operator for publication. A published version is immutable; a correction is issued as a new version rather than an edit.
1. What this policy is, and who it binds
This Acceptable Use Policy (the "Policy") governs what may and may not be done with Pack & Kin Studio. It is incorporated by reference into the Platform Terms of Service, the Dealer Agreement and the Developer Terms, and a breach of this Policy is a breach of whichever of those you are party to.
It binds: a store and everyone acting under its account, including its staff and contractors; a dealer or sales representative; and a third-party developer or integration acting on a store's behalf.
Capitalized terms not defined here have the meaning given in the Platform Terms of Service. "Pack & Kin" means Mail and More LLC, an Arizona limited liability company; Pack & Kin and Pack & Kin Networks are its trademarks.
A note on how to read it. This Policy states outcomes, not an exhaustive catalogue. Conduct that is plainly within the spirit of a prohibition is prohibited even if it is not itemized, and we will say so plainly rather than argue about a list.
2. General prohibitions
You will not, and will not permit anyone to, use the Services to:
- (a) violate any law, regulation, court order, or the rules of a Carrier, payment network, postal authority or other third party whose services reach you through the Services;
- (b) infringe or misappropriate anyone's intellectual property, publicity, or privacy rights;
- (c) transmit, host or distribute malware, ransomware, or any code intended to damage, disable or gain unauthorized access to a system;
- (d) conduct phishing, credential harvesting, or any scheme to obtain information by deception;
- (e) engage in fraud, money laundering, structuring, or the sale of stolen goods or data;
- (f) harass, threaten, defame, or facilitate violence or harm against any person;
- (g) exploit or endanger a minor in any way;
- (h) interfere with the operation, integrity or security of the Services, another customer's use of them, or any network or system reached through them;
- (i) misrepresent your identity, your affiliation with Pack & Kin, or the origin of anything you transmit;
- (j) access, or attempt to access, data belonging to another store, another customer, or Pack & Kin, other than through the interfaces provided to you;
- (k) circumvent or attempt to circumvent entitlement gates, metering, quotas, rate limits, permissions, or any technical measure that enforces what your plan includes; or
- (l) resell, sublicense, or make the Services available to a third party as a service bureau, except as your own store operations expressly permit.
3. Shipping, mailing and prohibited items
3.1 Your shipping obligations are in the Terms. Schedule B.3 of the Platform Terms of Service states what you may and may not ship, your declaration obligations, and your customs and export duties. This section does not restate that list — it adds the conduct rules and states what happens when a rule is broken.
3.2 Conduct prohibitions. You will not use the Services to:
- (a) ship on behalf of an undisclosed third party, or operate a reshipping, drop-shipping or freight-forwarding scheme in which the true shipper is concealed from the Carrier;
- (b) ship goods bought with stolen payment credentials, or participate in reshipping fraud (sometimes presented to a store as a "package forwarding job");
- (c) misdeclare weight, dimensions, contents, value or commodity classification to obtain a lower rate or to evade a Carrier restriction, a duty, or an export control;
- (d) split a shipment to evade a declaration threshold, a licence requirement or a Carrier limit;
- (e) use a service, rate, account or agreement you are not entitled to, including a rate obtained by misrepresenting the nature of your business;
- (f) tender undeclared hazardous materials, which is separately a material breach of the Terms and a ground for immediate termination; or
- (g) use the Services to ship anything for a person or entity on a U.S. sanctions or denied-party list, or to an embargoed destination.
3.3 We do not inspect. Consistent with Schedule B.3.1, we do not inspect, screen, weigh, verify or monitor shipments, and we have no duty to do so. Screening prompts and classification aids in the product are conveniences. Their presence does not make a violation ours.
4. Mailbox, mail receiving and CMRA conduct
If you operate a mailbox or mailroom service, Schedule D of the Terms sets out your CMRA obligations. In addition, you will not:
- (a) deliver mail to a person for whom you do not hold a properly executed and verified PS Form 1583;
- (b) knowingly provide a mailbox address to a person you believe intends to use it to perpetrate fraud, to misrepresent a business location, or to evade service of process;
- (c) open, withhold, divert or destroy mail other than as USPS rules and applicable law permit;
- (d) obstruct, delay or refuse a lawful inspection or request from the U.S. Postal Inspection Service or other authority; or
- (e) disclose a mailbox customer's identity, address, forwarding address or identification records except as law requires or permits.
Cooperation. If a postal authority or law-enforcement agency contacts us about your mailbox operation, we may provide records we hold and will generally notify you unless we are prohibited from doing so or believe notice would create a risk to a person or an investigation.
5. Outbound email and messaging
Status note. Customer SMS is not enabled at launch. This section is written to cover it because the capability exists in the product and will be switched on; until it is, the rules below apply to email.
5.1 You are the sender. For any message sent to your customers through the Services — marketing campaigns, receipts, arrival notices, review requests — you are the sender and the party responsible for it. We provide the transport. We are not the sender, do not select your audience, and do not review your content.
5.2 Consent. You will send commercial messages only to people who have given you a lawful basis to contact them, and you will comply with the CAN-SPAM Act, the Telephone Consumer Protection Act and applicable state analogues. For SMS, that means prior express written consent where the law requires it, and it is your responsibility to obtain and evidence it.
5.3 Two independent records of "no". The product maintains two separate suppression signals — a customer's marketing-consent setting, and a campaign unsubscribe. Both are honored, independently. You will not:
- (a) clear, overwrite or work around either signal in order to reach someone who has said no;
- (b) re-add an unsubscribed person to an audience by re-importing them; or
- (c) move a person to a different list, channel or sending identity to evade a suppression.
5.4 List practices. You will not send to purchased, rented, scraped or harvested lists, or to addresses obtained other than through your own relationship with the person. You will keep your lists current and will not repeatedly send to addresses that hard-bounce.
5.5 Content and headers. Every commercial message must accurately identify you as the sender, carry a functioning unsubscribe mechanism, honor an unsubscribe promptly, and include a valid physical postal address. You will not falsify headers, sending identity, or the subject line's relationship to the content.
5.6 Deliverability is shared infrastructure. Outbound mail may traverse infrastructure shared with other stores. A store that generates complaints, spam-trap hits or blocklistings degrades delivery for everyone else on it. We therefore treat sending abuse as urgent, and we may suspend sending on complaint metrics alone, before any determination that a law was broken.
5.7 Volume. We may apply sending limits and may require you to warm up a new sending volume.
6. Websites, storefronts and hosted content
6.1 You are the publisher. Where we host a website, storefront or page on your behalf, you are its author and publisher. You are responsible for its content, its own privacy and cookie disclosures, its accessibility, and any consent it collects.
6.2 Prohibited content. You will not publish, host or link to: content that infringes intellectual property; malware or phishing pages; content that is obscene, that sexualizes minors, or that is unlawful to distribute; content promoting violence or unlawful activity; or content that misrepresents an affiliation with Pack & Kin, a Carrier, or a government agency.
6.3 Resource use. You will not use hosting for cryptocurrency mining, proxying or tunnelling third-party traffic, bulk file distribution unrelated to your business, or any workload that degrades shared infrastructure.
6.4 Copyright complaints. If you believe content hosted through the Services infringes your copyright, email abuse@packandkin.net with enough detail to identify the material, where it appears, and your rights in it. We will review it and may remove or disable access to the material, and suspend or terminate the account responsible, under Section 9.
We do not operate a statutory notice-and-takedown process and maintain no designated agent under 17 U.S.C. §512. Nothing in this Policy creates one, and no communication to us constitutes service of a statutory notice. Our response to a copyright complaint is the contractual one described above and in Section 9, taken at our discretion.
7. Automated access, APIs and data extraction
7.1 You may access the Services programmatically only through the documented APIs, using credentials issued to you, and within published rate limits.
7.2 You will not: scrape or crawl the Services; use automated means to extract data at a scale or frequency the interface was not designed for; probe, scan or load-test the Services except as §8 permits; or use the Services to build or train a competing product.
7.3 We may throttle, suspend or revoke credentials that generate abnormal load, and we may do so immediately and without notice where the load threatens availability for others.
7.4 Credentials. API keys and tokens are issued to you and are yours to protect. You will not share them, embed them in client-side code, or transfer them with a sale of your business without our consent.
8. Security research and vulnerability disclosure
We would rather hear about a problem from you than from an incident.
8.1 How to report. Email security@packandkin.net. Our published security policy sets out what to include, our acknowledgement and assessment timelines, and the safe-harbour commitment we make to good-faith researchers. That policy governs — this section points at it and does not restate it.
8.2 What good faith means here. Testing is in scope only where you: use your own account and your own test data; stop as soon as you have established that a vulnerability exists; and do not access, modify, copy, retain or exfiltrate another store's data.
This platform holds several stores' customers, wallet balances, merchant-boarding identity material and USPS Form 1583 identity documents in one database, separated by tenant scoping and Postgres Row-Level Security. If you find a way across that boundary, stop, and say so prominently in your report.
8.3 Out of scope. Denial-of-service and load testing; social engineering of our staff, a store's staff, or a customer; physical intrusion; and any testing against a store's live production data without that store's written authorization.
8.4 We will not pursue action against a researcher who follows §8.1–8.3. Conduct outside them is not security research and is treated under §9.
9. Enforcement — what we do, and in what order
9.1 The default order. Where circumstances permit, we escalate:
- Notice. We tell you what we have seen and what has to change, and give you a reasonable opportunity to fix it.
- Narrow suspension. We suspend the specific function involved — sending, label purchasing, hosting, API access — and leave the rest of your account working.
- Account suspension. Staff access is blocked; data is intact.
- Termination. Under Section 7.4 of the Terms.
9.2 When we skip straight to the end. We may suspend or terminate immediately and without prior notice where there is: undeclared hazardous material; a credible risk to a person's safety; suspected fraud or unauthorized access; a demand from a Carrier, payment network, processor or authority; a legal obligation; or conduct that threatens the security or availability of the Services for others.
9.3 What else we may do. Void or refuse a label; remove or disable content; preserve and produce records to a Carrier, a payment network or an authority; and charge you any fine, penalty, adjustment, return, disposal or handling cost imposed on us as a result of your conduct, which we may debit from your Wallet.
9.4 Suspension is not a holiday from fees. Fees continue to accrue during a suspension, as Section 6.4 of the Terms provides.
9.5 Reinstatement. We may require evidence that the cause has been remedied, and we may decline to reinstate.
9.6 No obligation to monitor. We may, but are not required to, monitor use of the Services. Not acting on a violation is not a waiver, and does not prevent us from acting on it or on a later one.
10. Reporting abuse
To report a violation of this Policy — including a shipment, a message, a mailbox, or a hosted site — email abuse@packandkin.net. Include what you saw, where, and when. Security vulnerabilities go to security@packandkin.net under §8, not here.
11. Changes to this Policy
We may revise this Policy under Section 2.3 of the Platform Terms of Service. Because this Policy also carries requirements imposed on us by Carriers, payment networks and postal authorities, a change required by one of them may take effect immediately under Section 2.4 of the Terms, and we will notify you as soon as reasonably practicable.